CVE-2008-2276: CSRF
Published May 16, 2008
·Updated
Cross-site request forgery (CSRF) vulnerability in manageusercreate.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.
Affected Software
1 affected component
Matisbt Mantis=1.1.1
Event History
May 16, 2008
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2276?
CVE-2008-2276 is classified as a medium severity vulnerability due to its potential for misuse via cross-site request forgery.
2
How does CVE-2008-2276 work?
CVE-2008-2276 allows remote attackers to exploit a cross-site request forgery vulnerability to create new administrative users in Mantis 1.1.1.
3
Who is affected by CVE-2008-2276?
CVE-2008-2276 affects users of Mantis version 1.1.1.
4
How do I fix CVE-2008-2276?
To fix CVE-2008-2276, upgrade Mantis to a version that addresses this vulnerability.
5
What are the potential impacts of CVE-2008-2276?
The potential impacts of CVE-2008-2276 include unauthorized access to administrative features and potential information breaches.